A-21
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix A Intrusion Detection System Architecture
System Components
•
Maintaining the blocking state across NAC restarts
NAC reapplies blocks that have not expired when a shutdown/restart occurs.
NAC removes blocks that have expired while it was shut down.
Note
NAC can only maintain the blocking state successfully if no one
changes the system time while the application is shut down.
See
Maintaining State Across Restarts, page A-23
, for more information.
•
Maintaining blocking state across network device restarts
NAC reapplies blocks and removes expired blocks as needed whenever a
network device is shut down and restarted. NAC is not affected by
simultaneous or overlapping shutdowns and restarts of NAC.
•
Authentication and authorization
NAC can establish a communications session with a network device that uses
AAA authentication and authorization including the use of remote
servers.
•
Two types of blocking
NAC supports host blocks and network blocks. Host blocks are connection
based or unconditional. Network blocks are always unconditional.
See
Connection-Based and Unconditional Blocking, page A-24
, for more
information.
•
NAT addressing
NAC can control network devices that use a Native Address Translation
(NAT) address for the sensor. If you specify a NAT address when you
configure a network device, that address is used instead of the local IP address
when the sensor address is filtered from blocks on that device.
•
Single point of control
NAC does not share control of network devices with administrators or other
software. If you must update a configuration, shut down NAC until the change
is complete. You can enable/disable NAC through the IDS CLI or any IDS
manager. When NAC is reenabled, it completely reinitializes itself, including
rereading the current configuration for each controlled network device.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...